CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10440 | CVE-2004-2014 | Candidate | Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10439 | CVE-2004-2013 | Candidate | Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10438 | CVE-2004-2012 | Candidate | The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10437 | CVE-2004-2011 | Candidate | msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10436 | CVE-2004-2010 | Candidate | PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18856 of 20943, showing 5 records out of 104715 total, starting on record 94276, ending on 94280